Queensland sees surge in public-sector data breaches and privacy complaints
Queensland's Office of the Information Commissioner recorded 82 data-breach notices and 353 privacy complaints last financial year, each more than double the prior totals.
In its latest annual report, Queensland’s Office of the Information Commissioner disclosed 82 data-breach notifications for the last financial year, up from 53 the year before, following the introduction of a compulsory breach-notification framework in July 2025. The majority of breaches were accidental, involving unauthorized disclosures like mis-sent emails, though a small number were intentional, exemplified by the Canvas platform incident affecting an education-technology provider.
The mandatory scheme obliges ministers, departments and local governments to inform both the commissioner and affected individuals of eligible breaches that could cause serious harm. The office also received a record 353 privacy complaints, more than twice the previous count, with 16 cases referred to the Queensland Civil and Administrative Tribunal. Cyber-security consultant Luke Irwin cautioned that under-reporting persists and that some agencies may lack qualified staff to assess potential harm, especially for vulnerable individuals such as domestic-violence survivors.
Why it matters
Rising breaches and complaints highlight growing privacy risks and the need for stronger data-protection enforcement in Queensland.
In this story
